VYPR
Unrated severityNVD Advisory· Published Sep 6, 2023· Updated Sep 27, 2024

CVE-2023-31188

CVE-2023-31188

Description

A network-adjacent authenticated attacker can execute arbitrary OS commands on multiple TP-LINK Archer routers via an unspecified command injection vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A network-adjacent authenticated attacker can execute arbitrary OS commands on multiple TP-LINK Archer routers via an unspecified command injection vulnerability.

Vulnerability

CVE-2023-31188 is an OS command injection vulnerability (CWE-78) affecting multiple TP-LINK Archer routers. The affected products and firmware versions are: Archer C50 firmware prior to 'Archer C50(JP)_V3_230505', Archer C55 firmware prior to 'Archer C55(JP)_V1_230506', and Archer C20 firmware prior to 'Archer C20(JP)_V1_230616' [4]. The vulnerability exists in an unspecified input field or function that does not properly sanitize user-supplied data, allowing injection of arbitrary OS commands.

Exploitation

An attacker must be on the same network as the target router (network-adjacent) and possess valid authentication credentials (e.g., administrator username/password) [4]. With authenticated access, the attacker can craft a malicious request containing OS commands and send it to a vulnerable endpoint. The vulnerability is reachable without user interaction beyond the attacker's own actions.

Impact

Successful exploitation allows the attacker to execute arbitrary OS commands on the router with the privileges of the web server process, likely leading to full compromise of the device (e.g., information disclosure, configuration modification, denial of service, or use as a pivot point in the network) [4]. The impact is limited to the router itself.

Mitigation

Update to the fixed firmware versions: Archer C50(JP)_V3_230505, Archer C55(JP)_V1_230506, or Archer C20(JP)_V1_230616, as applicable [1][2][3][4]. No workarounds are documented; affected users should apply the official firmware updates from the TP-Link download pages [1][2][3].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

6
  • Range: <Archer C20(JP)_V1_230616
  • Range: <Archer C55(JP)_V1_230506
  • Range: <Archer C50(JP)_V3_230505
  • TP-Link/Archer C60cpe-rescue3 versions
    firmware versions prior to 'Archer C20(JP)_V1_230616'+ 2 more
    • (no CPE)range: firmware versions prior to 'Archer C20(JP)_V1_230616'
    • (no CPE)range: firmware versions prior to 'Archer C50(JP)_V3_230505'
    • (no CPE)range: firmware versions prior to 'Archer C55(JP)_V1_230506'

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

4

News mentions

0

No linked articles in our index yet.